§02c Jupiter — Non-Language Bridge — Externally-observable properties
Mars® Spec › §02c Jupiter — Non-Language Bridge › Externally-observable properties
11. Externally-observable properties
Inbound boundary:
| Property | Observable condition |
|---|---|
| NB1 — No cross-store arithmetic | Attempt cross-store score comparison without registered calibration mapping; observe discharge module refusal |
| NB1 — Joint-authority attestation required | Submit a calibration mapping with attestation from only one store owner; observe refusal at registration — the joint-authority attestation hash fails recomputation from a single signature |
| NB1 — Canonical-space enforcement | Submit a comparison under a registered mapping using raw native scores rather than f₁/f₂ mapped scores; observe gate refusal — comparison on raw native scores is not admitted even under a registered mapping |
| NB1 — Falsifier: embedder re-training | Change the model-weight hash of one store’s embedder; observe automatic mapping invalidation and audit-trail cascade records for comparisons within the retention window |
| NB1 — Falsifier: joint-authority withdrawal | Withdraw one store owner’s attestation; observe joint-authority hash recomputation failure and mapping invalidation |
| NB1 — Scope exit under registered mapping | Submit a comparison whose typed scope exits the mapping’s scope-of-applicability certificate; observe per-request refusal; confirm mapping validity state unchanged |
| NB1 — Embedder version mismatch | Submit a comparison request whose embedder version does not match the version recorded in the mapping’s store-identity fields; observe refusal |
| Anchor absent/present differential | Submit predicate with and without anchor; observe distinct outcomes at downstream gate |
| Signature validity differential | Submit predicate with tampered anchor signature (covers Fields 1–7); observe refuse |
| Registered-identity differential | Submit predicate with unregistered program_id (Field 1), analysis-spec_id (Field 4), or interp-gen-spec_id (Field 5); observe refuse on each |
| Causal-closure recomputation | Submit predicate with modified engineering-result content hash (Field 3); observe refuse |
| Input-data identity absent | Submit predicate with Field 2 (input-data identity) missing; observe refuse at downstream gate — Field 2 is independently required |
| Bridging-program certification absent | Submit predicate with Field 1 certification record omitted; observe refuse — the engineering-program-identity invariant is not satisfied without the certification record |
| Co-signature requirement on interaction-mediated steps | Submit interaction-mediated execution record without co-signature; observe causal-closure failure |
Analysis of lifted artifacts and cross-domain composition (§3):
| Property | Observable condition |
|---|---|
| NB2 — No implicit equivalence | Attempt inter-domain predicate composition outside registry; observe refuse and knowledge-gap referral |
| NB2 — Sole-channel enforcement | Attempt to configure a second cross-domain composition path that bypasses the composition module; observe refusal at deployment registration with a structural diagnostic identifying the rejected configuration |
| NB2 — Domain determination by governing authority | Submit two predicates with identical surface vocabulary strings governed by distinct source authorities; observe that the composition module treats the composition as cross-domain and requires a registered interface |
| NB2 — Composition-execution witness causal binding (admission side) | Present an admitted cross-domain composition; recompute the target-domain predicate’s content hash from the source-domain predicate’s content hash under the named translation rule recorded in the cross-domain-provenance record; a match confirms causal binding; a mismatch indicates non-conformance regardless of interface identity co-presence |
| NB2 — Downstream refusal of non-re-deriving predicate | Submit a target-domain predicate with a cross-domain-provenance record whose composition-execution witness does not re-derive the presented predicate’s content hash; observe downstream gate refusal |
| NB2 — Knowledge-gap referral with joint authority from directory | Submit a cross-domain composition request for a pair with no registered interface; observe routing-with-trigger object emitted with routing destination set to the joint authority from the domain-authority directory; confirm the routing target is present in Field 3 of the registered object |
| NB2 — Knowledge-gap referral as routing-with-trigger object | Inspect the specification registry after a refusal; confirm the referral is registered as a seven-field routing-with-trigger object with attestation chain and trigger condition, not as a plain log entry; confirm the trigger-occurrence discharge module refuses discharge absent a satisfied trigger condition |
| NB2 — Retention-window expiry escalation | Allow the retention window of a registered referral object to elapse without joint-authority response; observe escalation trigger fired and recorded in the audit trail |
| NB2 — Closure record on corrective interface registration | Register a corrective cross-domain typed interface in response to a referral; observe closure record created naming the referral object, the corrective interface, and the closure timestamp; observe propagation to affected downstream consumers |
| NB2 — Interface bootstrap cross-authority requirement | Submit an interface bootstrap with attestation from only one domain’s reviewers; observe hard gate failure at registration |
| PV-gate anchor enforcement | Submit CertifiedBundle containing a predicate that arrived via the non-language bridge but lacks a complete non-language-provenance anchor; observe REFER and no bundle emission |
| Battery execution discipline | All §02a §3a observable properties (B1–B8) apply to lifted artifact analysis; see §02a §8 |
Outbound boundary and named-authority standing:
| Property | Observable condition |
|---|---|
| NB3 — Authority action required | Route certified output to consequence-bearing operation without recorded authority action; observe downstream-consumer guard refusal |
| NB4 — No model confidence gating | Load configuration naming model-internal confidence class; observe configuration-rejection diagnostic identifying the rejected signal class by name |
| NB4 — Derivation-binding witness enforcement | Present a candidate gating signal whose tag declares procedural-confidence but whose value was derived from model-internal state; the value does not re-derive from any PassRecord set under the named derivation function; observe refusal at the runtime gate irrespective of the tag |
| NB4 — Re-tagged model value refused | Present a value equal to the model’s softmax output, tagged as procedural-confidence, with a derivation-binding witness that does not re-derive it from a PassRecord set; observe gate refusal — the mechanism confirms gating rests on re-derivation, not label |
| NB4 — Differential gating behavior | Present predicate A with model-internal confidence c and procedural confidence above threshold; present predicate B with the same model-internal confidence c but procedural confidence below threshold; observe admit for A and defer/refuse for B; the differential demonstrates the gate tracks procedural confidence, not model-internal confidence, without internal inspection |
| NB4 — Audit record recomputability | Retrieve a procedural-confidence audit record from the audit trail; recompute the procedural-confidence value from the per-pass discharge record set against the declared derivation function; confirm the recomputed value matches the recorded value within tolerance without access to model-internal state |
| NB4 — Drift indicator emission | Observe a case where model-internal confidence is high and procedural confidence is low (confidently-wrong regime); confirm the drift indicator magnitude exceeds the declared threshold and the event is surfaced for human-authority review in the audit trail |
| NB5 — Scope match required | Present consumer bridging program input range outside certified scope; observe re-analysis trigger, not admission |
| NB3–NB5 priority | NB3 > NB4 > NB5: constructing inputs triggering paired refusals produces the higher-priority refusal record; lower-priority not consulted |
| Non-trivial transformation | Submit null-transformation causal-binding witness for non-pass-through actuation class; observe gate-check failure under condition 6 |
| Actuation anchor structural-invariant refusals 1–8 | Exercise each condition independently; observe distinguishable typed refusal reason per condition |
| Standing coverage check | Submit co-signature from authority whose declaration does not cover the actuation class; observe gate-check failure under condition 8 |
| Standing lifecycle — scope-restricting | Amend standing declaration narrowing consequence-bearing class set or declared scope; observe scope-restricting cascade on in-flight actuation anchors |
| Standing lifecycle — revocation | Revoke standing declaration; observe immediate invalidation of in-flight actuation anchors referencing the revoked authority and audit-trail cascade records |
| Standing — issuing-authority signature check | Submit a recorded action under a declaration whose issuing-authority signature (Field 5) has been tampered; observe refusal at discharge module check 4 |
| Standing — temporal validity expiry | Submit a recorded action under a declaration whose temporal validity window has elapsed; observe refusal at check 5 without querying revocation |
| Standing — revocation-reference query | Submit a recorded action under a revoked declaration (revocation-reference indicates revoked); observe refusal at check 6 and cascade records created in audit trail |
| Standing — scope insufficiency | Submit a recorded action by an authority whose declared scope does not cover the operation’s typed scope; observe refusal at check 7; submit same action within declared scope; observe admission — differential behavior without internal inspection |
| Enumeration coverage | Submit a recorded action referencing a consequence-bearing class absent from the registered enumeration; observe refusal at check 1 |
| Declaration absent | Submit a recorded action by a named authority with no registered declaration for the consequence-bearing class; observe refusal at check 2 |
| Cascade through audit trail | Revoke a standing declaration; query audit trail; observe typed cascade records for all recorded actions performed under the declaration within the retention window; observe refusal of subsequent emission for non-linguistic effects under actuation anchors carrying those recorded actions |
Scope certificates and N-hop composition:
| Property | Observable condition |
|---|---|
| Falsifier-cascade on spec amendment | Amend a scope-breaking specification (§02b §5); observe scope-of-applicability certificate invalidation within retention window |
| Any-link withdrawal invalidation | Withdraw one interface Iₖ; observe immediate invalidation of all composed certificates traversing that link |
| Atomicity of partial re-discharge | Attempt re-discharge of a proper subset of composition hops; observe COMPOSITION-PATH-INVALID refusal |
| Scope monotone narrowing | Construct composition path; verify composed scope ⊆ scope of each individual interface |
| Bidirectional closure declaration | Inspect governing specification for output-class routing declaration; verify actuation anchor deployed for all output classes routed to non-linguistic effects |
| Discharge module five-check sequence | Submit a certified predicate to a re-entrance event: first with a tampered certificate signature — observe refusal at check 1; then with the certificate on the invalidation log — observe refusal at check 2; then with consumer input range outside certified scope — observe per-request refusal at check 3; confirm the certificate’s validity state is unchanged after the check-3 refusal |
| Discharge record external verifiability | Retrieve a discharge record from the audit trail; recompute the signature over (predicate content hash ‖ certificate identifier ‖ consumer input range ‖ admission decision); confirm it matches the recorded signature without access to the internal implementation |
| Scope exit per-request only | Present two sequential consumer requests under the same certificate: the first with input range outside certified scope (scope exit), the second with input range inside certified scope; observe refusal for the first and admission for the second; confirm the certificate remains valid and its validity state is unchanged between the two requests |
| Registered re-entrance obligation enforcement | Register a re-entrance participant; admit it; elapse the declared reporting window without the participant reporting a downstream certification content hash; observe the participant recorded as non-reporting and subsequent re-entrance requests from that participant refused pending resolution |
| Divergence-rate metric scope-cell independence | Construct two registered re-entrance participants whose admitted input ranges intersect but fall in distinct scope cells of the certificate’s finite partition; confirm neither participant is included in the other’s equivalence class for divergence-rate computation; confirm divergence-rate is computed within each scope cell independently |
| Divergence-rate metric recomputability | Retrieve audit trail records for a set of registered re-entrance participants under a certificate; independently recompute the divergence-rate metric from the reported downstream certification content hashes using the declared typed-disagreement relation and scope-cell partition; confirm it matches the published metric value |
| Threshold-triggered alert | Configure a divergence-rate threshold on a certificate; drive the disagreement ratio within one scope cell above the threshold; observe a typed alert emitted and recorded in the audit trail and reported to the certifying authority |
Deployment registry and enforcement-artifact-signatures:
| Property | Observable condition |
|---|---|
| Architecture-identifier recomputability | Retrieve the deployment registry; recompute the architecture-identifier as a content hash over the five per-mechanism rows in R1–R5 order; confirm it matches the registered value |
| Mechanism-kind enumeration coverage | Each of the five registered mechanism rows carries a mechanism-kind value drawn from the typed enumeration {typed-module-interface-refusal, registry-membership-check-refusal, recorded-action-condition-refusal, configuration-rejection-module-refusal, scope-match-discharge-refusal}; no row carries a value outside this enumeration |
| Enforcement-artifact-signature distinguishability | Present a candidate violating operation to each of the five mechanisms independently; observe that the refusal record emitted by each mechanism carries a mechanism-name and mechanism-kind value distinct from every other mechanism’s refusal record and from an admit record; each observed record matches the enforcement-artifact-signature registered for that mechanism in the deployment registry |
| Architecture-identifier change on field modification | Modify any single field in any per-mechanism row of the deployment registry; observe that the recomputed architecture-identifier produces a distinct content hash; downstream consumers verifying against the prior architecture-identifier are observably unable to transparently consume outputs from the modified architecture |
| Concurrent non-weakening observable | Present candidate operations triggering refusals at two or more mechanisms simultaneously; observe that the higher-priority mechanism’s refusal record is emitted and that the lower-priority mechanism’s evaluation capability is not disabled — re-submitting a candidate that triggers only the lower-priority mechanism produces that mechanism’s refusal record, confirming it remains active |
| Monotonic non-refusal configuration refused | Submit a deployment configuration declaring monotonic non-refusal for any of the five mechanisms; observe refusal at deployment registration with a structural diagnostic identifying the rejected declaration |
Refusal conformance test harness:
The five structural refusals are conformance-testable by an independent inspector without inspection of internal implementation. The conformance test harness is a publishable set of test vectors — one per refusal — presented to the deployment, with expected responses declared in the registered architectural specification. A deployment is compliant if and only if all five expected responses are observed, each refusal record matching the enforcement-artifact-signature registered in the deployment registry for the respective mechanism.
| Test | Candidate operation | Expected response |
|---|---|---|
| T1 (R1) | A federated-retrieval request performing cross-store score arithmetic across two stores with distinct embedders without a registered cross-store calibration mapping | Refusal at the federated-retrieval module; refusal record carries mechanism-kind = typed-module-interface-refusal |
| T2 (R2) | A cross-domain predicate composition request not naming a registered cross-domain typed interface | Routing to knowledge-gap referral; refusal record carries mechanism-kind = registry-membership-check-refusal |
| T3 (R3) | A downstream consumption attempt treating a certified output as authoritative without a recorded named-authority action on the audit trail | Blocked consumption; refusal record carries mechanism-kind = recorded-action-condition-refusal |
| T4 (R4) | A deployment-registration request naming a model-internal-confidence signal class as a gating input | Rejection at registration with a structural diagnostic identifying the rejected class; refusal record carries mechanism-kind = configuration-rejection-module-refusal |
| T5 (R5) | An out-of-scope re-entrance of a certified predicate at a consumer whose input range falls outside the predicate’s scope-of-applicability certificate | Re-analysis trigger; divergence-rate metric updated; refusal record carries mechanism-kind = scope-match-discharge-refusal |
The test vectors and expected responses are publishable artifacts. A licensee may publish them; a downstream consumer may run the tests against a candidate system to verify conformance. Conformance is binary: producing the expected response to all five tests establishes conformance; producing a non-expected response to any test identifies which refusal is not enforced.
Interaction-protocol lift:
| Property | Observable condition |
|---|---|
| Protocol-specification lift link present in witness chain | Where target is interaction-mediated, witness chain carries a protocol-specification lift link before analysis-act links |
| Trace-record lift link present in witness chain | Where target is interaction-mediated, witness chain carries a trace-record lift link before analysis-act links |
| Untyped-pending trace elements produce declared-irreducible entries | Submit trace with transitions not assignable to any declared order; observe declared-irreducible entries and narrowed certified scope in Field 5 |
Indexed boundary properties (IB1–IB19, J1–J16). The following indexed properties are the canonical numbered observables for the integrated boundary (inbound, composition gate, scope certificates) and the actuation boundary. The differential procedures above exercise them; Appendix B carries the same properties with inspector-verifiability and licensing-tier columns.
| Property | Observable condition |
|---|---|
| IB1 — Admit/refuse differential by anchor presence | Predicate with and without anchor produces distinct outcomes |
| IB2 — Admit/refuse differential by signature validity | Predicate with tampered anchor signature is refused |
| IB3 — Admit/refuse differential by registered identity | Predicate with unregistered program_id, spec_id, or interp-gen-spec_id is refused on each |
| IB4 — Causal-closure recomputation | Predicate with modified engineering-result content hash is refused |
| IB5 — Co-signature requirement on interaction-mediated steps | Interaction-mediated execution record without co-signature produces causal-closure failure |
| IB6 — R1 — no cross-store arithmetic | Attempt cross-store score comparison without registered calibration mapping produces module-construction refusal |
| IB7 — Mechanical tri-state of composition gate | Pass sets with known (passed, has_falsifier) distributions produce CERTIFY/REFUSE/REFER deterministically |
| IB8 — Pipeline termination on AR-gate / PV-gate | Authority conflict or missing faithfulness attestation produces no subsequent pass execution and a single REFER record |
| IB9 — Audit chain tamper evidence | Modification of a prior pass record produces a chain hash mismatch |
| IB10 — Re-entrance detection at the inbound boundary | Composition invoking same (analysis-spec-identity, pass-name) twice in one session produces REFUSE with cycle descriptor; this is the inbound-boundary observation of the re-entrance discipline (§02a §3a.4), whose battery-layer property is B4 |
| IB11 — Substrate version guard | Cached result with mismatched substrate_version_tuple is rejected |
| IB12 — Battery-method-identity linkage | PassRecord battery_method_identity traces to a §02a battery method entry in the multi-stage witness chain |
| IB13 — Procedural-confidence recomputability | Procedural-confidence value is re-derived from PassRecord set using declared weights and normalization; observed match with issued value |
| IB14 — R2 — no implicit equivalence | Inter-domain predicate composition outside registry produces refuse and knowledge-gap referral |
| IB15 — Falsifier-cascade on spec amendment | Scope-breaking specification amendment produces scope-of-applicability certificate invalidation within retention window |
| IB16 — Any-link withdrawal invalidation | Withdrawal of one interface link produces immediate invalidation of all composed certificates traversing that link |
| IB17 — Atomicity of partial re-discharge | Re-discharge of a proper subset of composition hops produces COMPOSITION-PATH-INVALID refusal |
| IB18 — Scope monotone narrowing | Composed scope ⊆ scope of each individual interface along the composition path |
| IB19 — Outbound-boundary declaration | Governing specification carries an output-class routing declaration; actuation anchor is deployed for all output classes routed to non-linguistic effects |
| J1 — Structural-invariant refusals | Each of the nine refusal conditions (§4.3) is independently exercisable; each produces a distinguishable typed refusal reason |
| J2 — Non-trivial transformation | Null-transformation causal-binding witness for non-pass-through actuation class produces gate-check failure under condition 6 |
| J3 — Procedural-confidence floor | CertifiedBundle with PassRecord inputs deriving below-floor value produces refuse under condition 7 |
| J4 — Model-internal confidence rejection | Deployment configuration naming a softmax or log-likelihood signal as gating input is rejected at load time |
| J5 — Causal-binding re-derivation | Anchor with modified originating predicate content hash produces condition 6 failure |
| J6 — R3 — authority action required | Certified output routed to a consequence-bearing operation without recorded authority action produces downstream-consumer guard refusal |
| J7 — R4 — no model confidence gating | Configuration naming model-internal confidence class is rejected at load with configuration-rejection diagnostic |
| J8 — R5 — scope match required | Consumer bridging program input range outside certified scope produces re-analysis trigger, not admission |
| J9 — R5 — divergence-rate metric recomputability | Divergence-rate metric re-derived from audit trail matches published metric without internal inspection |
| J10 — R3 over R5 priority | Input triggering both R3 and R5 simultaneously produces R3 refusal record; R5 not consulted |
| J11 — R3 over R4 priority | Input triggering both R3 and R4 simultaneously produces R3 refusal record; R4 not consulted |
| J12 — R4 over R5 priority | Input triggering both R4 and R5 simultaneously produces R4 refusal record; R5 not consulted |
| J13 — Named-authority standing coverage check | Co-signature from authority whose declaration does not cover the actuation class produces gate-check failure under condition 8 |
| J14 — Named-authority standing lifecycle — scope-restricting | Amendment narrowing authorized-actuation-classes produces scope-restricting cascade on in-flight actuation anchors referencing that authority |
| J15 — Named-authority standing lifecycle — revocation | Revocation of standing declaration produces immediate invalidation of in-flight actuation anchors referencing the revoked authority |
| J16 — Concurrent non-weakening | Deployment registry carries all five refusals; priority-order enforcement is observable by constructing inputs triggering pairs of refusals at different priority levels |
| AC1 — Accumulation record present and order-structured | Each admitted effect in an accumulation-governed class appends an order-typed, witness-bound entry (class, order tags, effect hash, target, timestamp, anchor reference) to the declared scope’s hash-chained accumulation record |
| AC2 — Joint-inadmissibility refusal at the accumulating effect | A sequence of individually-admissible effects that is jointly out-of-bounds under a declared accumulation predicate is refused at the accumulating effect with typed refusal accumulation-bound-exceeded identifying the violated predicate and contributing entries |
| AC3 — Declared accumulation scope enforced | Accumulation scopes and windows are registered parameters of the runtime configuration record; an actuation class with declared accumulation predicates operating without the accumulation gate is non-conforming |
| AC4 — Decomposition foreclosure | Submitting a macro-effect decomposed into individually-admissible micro-effects produces refusal at the bound regardless of per-effect admissibility; per-effect-only gating does not practice accumulation governance |
| IB20 — Persistent-state writes declared and actuation-gated | A certified output routed to persistent state whose content can influence a subsequent governed invocation is an emitted effect under the actuation anchor and gate; a routing declaration omitting such a class is incomplete and the write is an ungoverned effect |